CVE-2012-5952
Last modified
CVE-2012-5952 is a vulnerability of currently unknown severity. IBM WebSphere Message Broker 6.1 before 6.1.0.12, 7.0 before 7.0.0.6, and 8.0 before 8.0.0.2 does not validate Basic Authentication credentials before proceeding to WS-Addressing and WS-Security operations, which allows remote attackers to trigger transmission of unauthenticated messages via unspecified vectors.. EPSS estimates a 1.39% chance of exploitation in the next 30 days.
Description
IBM WebSphere Message Broker 6.1 before 6.1.0.12, 7.0 before 7.0.0.6, and 8.0 before 8.0.0.2 does not validate Basic Authentication credentials before proceeding to WS-Addressing and WS-Security operations, which allows remote attackers to trigger transmission of unauthenticated messages via unspecified vectors.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Websphere Message Broker | 6.1 |
| Ibm | Websphere Message Broker | 6.1.0.1 |
| Ibm | Websphere Message Broker | 6.1.0.2 |
| Ibm | Websphere Message Broker | 6.1.0.3 |
| Ibm | Websphere Message Broker | 6.1.0.4 |
| Ibm | Websphere Message Broker | 6.1.0.5 |
| Ibm | Websphere Message Broker | 6.1.0.6 |
| Ibm | Websphere Message Broker | 6.1.0.7 |
| Ibm | Websphere Message Broker | 6.1.0.8 |
| Ibm | Websphere Message Broker | 6.1.0.9 |
| Ibm | Websphere Message Broker | 6.1.0.10 |
| Ibm | Websphere Message Broker | 6.1.0.11 |
| Ibm | Websphere Message Broker | 7.0. |
| Ibm | Websphere Message Broker | 7.0.0.1 |
| Ibm | Websphere Message Broker | 7.0.0.2 |
| Ibm | Websphere Message Broker | 7.0.0.3 |
| Ibm | Websphere Message Broker | 7.0.0.4 |
| Ibm | Websphere Message Broker | 7.0.0.5 |
| Ibm | Websphere Message Broker | 8.0 |
| Ibm | Websphere Message Broker | 8.0.0.1 |
References
- http://www-01.ibm.com/support/docview.wss?uid=swg21623316Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21623316Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-5952?
How severe is CVE-2012-5952?
How do I fix CVE-2012-5952?
Are you affected by CVE-2012-5952?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
